Knowledge Base

Regulation

NIS2: 8,000 Dutch companies will raise supplier security requirements

Your largest customer asks whether your cybersecurity is in order. Under NIS2, more Dutch businesses will start asking their suppliers exactly that.

25 November 2025 SpySecure SpySecure

A call from your largest customer. Normally, that is a call you are happy to receive. Unless they are calling to ask about your cybersecurity. Because then you know: you need to take action.

Major supermarket chains have already announced it. And large companies in other sectors are beginning to follow:

“Large companies are going to screen their suppliers for cybersecurity. If you fail that screening, your commercial relationship will come under serious pressure.”

Let that sink in: your largest customer, the software company you have worked with for years, or the major contractor you deliver important projects for, will soon ask you: is your cybersecurity in order?

Can you provide evidence, such as a certificate?

No? Then there is a chance they will start looking for another supplier.

Henk Bijsterbosch told us this last week. As Manager of Knowledge Partners at Samen Digitaal Veilig, he brings together around 100 organisations – from cybersecurity companies to accountants and banks – that are working to improve cybersecurity in the Netherlands.

That means he hears from all sides what is really happening.

 

Your largest customers will require you to have your cybersecurity in order

“Those 8,000 companies covered by the Dutch Cybersecurity Act (NIS2),” Henk explained, “must ensure that their supply chains are secure.”

“Let me give you a random example: a major supermarket is an organisation subject to NIS2. It has a large number of suppliers. It will look at each supplier and ask: if this supplier can no longer deliver to me because of a hack or incident, what does that mean for my business continuity?”

That supermarket chain will therefore expect its suppliers to demonstrate that they are properly protected against cybercrime. And it will not simply take their word for it.

“Being able to demonstrate this effectively means obtaining a certification,” Henk explained. “Those 8,000 companies are being advised to amend their procurement contracts and require their suppliers to demonstrate – through certification – that they operate securely.”

 

Accountants, banks and insurers will also get involved

Large customers are not the only parties that will require SMEs to have their cybersecurity in order.

Henk explained: “An accountant is required to sign off a company’s annual accounts at the end of the year. They will ask: ‘Is your cybersecurity in order, and can you prove it?’ If you cannot provide evidence, this could result in a qualification or comment in your annual accounts. Naturally, no business wants that.”

When signing off annual accounts, accountants assess risks to business operations, particularly financial risks. Because a cyberattack can have a major financial impact, they increasingly want objective evidence that an organisation’s security is properly managed.

Banks and insurers will also become more involved in cybersecurity, for example when a company applies for insurance or financing.

“Banks always assess risk. They are already screening customers for cybersecurity when they apply for financing above a certain amount,” Henk said. “If your cybersecurity is not in order, they will ask questions – with the risk that your financing is rejected or additional conditions are imposed.”

 

Could you also become personally liable?

Why are organisations subject to NIS2 already taking this so seriously? “Under NIS2, the directors of these companies are personally and jointly liable,” Henk explained. “You can easily imagine that they will say: I am going to transfer the risks created by my high-risk suppliers through my supplier contracts.”

“Under NIS2, the directors of these companies are personally and jointly liable.”

That is not surprising.

If you are personally liable as a director for cybersecurity incidents in your supply chain, you naturally do not want to carry that risk alone. So what do you do? You pass part of that liability on to your suppliers.

In other words: if your security is inadequate and this causes problems for a major customer, you could potentially be held personally liable as a business owner.

 

But isn’t cybersecurity extremely complicated?

It is clear that cybersecurity can no longer be ignored, even by SME owners.

Not only to protect your business, but also for commercial reasons – for example, if you want to retain your largest customers or attract new ones.

The problem is that many business owners believe cybersecurity is extremely complicated. They think they need to understand everything before they can take action.

But that is not necessary. You do not need to be an accountant to work effectively with an accountant either.

 

So what should you do?

Your largest customers and other stakeholders are expected to ask for evidence that your basic security measures are properly implemented. You can achieve this as follows:

Step 1: Have a security assessment performed

We assess your current position and identify any security gaps. This provides immediate insight into what still needs to be done to obtain the most widely used certification, the NIS2 Quality Mark.

Step 2: Put your basic security measures in place

Based on the assessment, we implement the most important measures for you: protecting your devices, workplaces, email, cloud environment, identities and backups, as well as providing employee training. This can often be arranged in one go with a complete cybersecurity package.

Step 3: Obtain your NIS2 Quality Mark certification

Our automated reports and compliance tool allow you to demonstrate that your security is in order and apply for certification. This enables you to show customers that you meet the relevant requirements.

 

What is the NIS2 Quality Mark?

To help organisations demonstrate that they are properly protected, ten major industry associations created the NIS2 Quality Mark. The certification has three levels – QM10 Basic, QM20 Substantial and QM30 High – aligned with the level of risk a supplier represents.

“98% of cyber incidents can be prevented by getting the basics right.”

For most SMEs, QM10 is sufficient. Henk explained: “98% of cyber incidents can be prevented by getting the basics right. And those basic measures are precisely what we have translated into the NIS2 Quality Mark Basic.”

 

NIS2 Quality Mark logo

 

 

Get your cybersecurity in order now and stay ahead of your competitors

Large organisations will require their suppliers and customers to demonstrate that they are properly protected. Those suppliers are often SMEs, and many SMEs do not yet meet the required minimum security level.

That also creates an opportunity: if many SMEs do not yet meet this required minimum level, you can create a significant competitive advantage by getting it in order now.

When demand suddenly increases and every company tries to address its cybersecurity at the same time, you will be able to confidently present your certification to both existing and prospective customers.

 

Do not wait until it is too late

We are seeing the urgency increase. The legislation will be introduced in the first half of 2026. That is much sooner than you may think, and at that point everyone will suddenly need support.

“But that capacity simply does not exist,” Henk said. He describes it as the “tsunami” that always arrives three months before new legislation takes effect.

An NIS2 Quality Mark also requires an audit. “It took us twenty years to conduct 5,000 audits, and soon we will need tens of thousands of audits every year. That will not be possible unless organisations start in time.”

“Soon we will need tens of thousands of audits every year. That will not be possible unless organisations start in time.”

His message is clear: do not wait until the legislation formally takes effect. Start now, because doing so will provide significant advantages.

Otherwise, there may no longer be sufficient capacity, there will be no time to address the requirements calmly, and you may suddenly need the certification immediately. “You do not want to be the business owner who eventually thinks: ‘What on earth have I been doing all this time?’” Henk said.

 

About Henk Bijsterbosch

Henk Bijsterbosch

Henk Bijsterbosch is Manager of Knowledge Partners at Samen Digitaal Veilig, an initiative of MKB-Nederland and VNO-NCW. He helps organisations and business owners improve their cybersecurity through practical guidance and plays an important role in making NIS2 legislation accessible to Dutch businesses. You can also connect with Henk on LinkedIn.

SpySecure is a partner of Samen Digitaal Veilig.